nerdexam
Cisco

350-201(NEW-127Q) · Question #4

The incident response team of an organization detects a compromised endpoint being used by a malicious actor who is encrypting and exfiltrating data. The incident response team stops the continued…

The correct answer is B. Evaluate the impact of the disclosed data. After containing a data breach by stopping the exfiltration, the immediate next step is to evaluate the impact of the disclosed data (B) - the team must understand what was taken, how sensitive it is, and who is affected before any other action can be taken, as this assessment…

Incident Response and Management

Question

The incident response team of an organization detects a compromised endpoint being used by a malicious actor who is encrypting and exfiltrating data. The incident response team stops the continued data leak. What must be the next step in this investigation?

Options

  • AEvaluate the policies violated by the disclosed data.
  • BEvaluate the impact of the disclosed data.
  • CUnencrypt and recover the exfiltrated data.
  • DNotify the external stakeholders of the disclosed data.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    79% (23)
  • C
    14% (4)
  • D
    3% (1)

Explanation

After containing a data breach by stopping the exfiltration, the immediate next step is to evaluate the impact of the disclosed data (B) - the team must understand what was taken, how sensitive it is, and who is affected before any other action can be taken, as this assessment drives every subsequent decision in the investigation.

Why the distractors fail:

  • A (Evaluate policies violated) - Policy analysis is a later-stage activity during the post-incident review, not the immediate follow-up to containment.
  • C (Unencrypt and recover the data) - Recovery efforts are relevant to remediation, but you cannot prioritize recovery without first knowing the scope and sensitivity of what was compromised.
  • D (Notify external stakeholders) - Notification is required, but only after you know what was disclosed; notifying without an impact assessment gives stakeholders meaningless or inaccurate information.

Memory tip: Think of the acronym C-I-N-R - Contain, Impact assess, Notify, Recover. Impact always comes right after containment because everything downstream (notifications, legal obligations, recovery priorities) depends on knowing what you actually lost.

Topics

#Incident Response#Impact Assessment#Data Exfiltration#Containment

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice